← Home

react-doctor

Diagnose and fix performance issues in your React app

2
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

abai

Keywords

accessibilitydiagnosticslinternextjsoxlintperformancereactreact-compilerreact-nativesecuritytanstacktypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/eslint-plugin.js AI (source-diff): Bundled ESLint plugin; sample shows lint logic, no dropper behavior. Stable FP for this package. ai
phantom-deps phantom-dep:agent-install AI (phantom-deps): Bundled dist output; likely used but not statically scannable. ai
phantom-deps phantom-dep:conf AI (phantom-deps): Bundled dist output; likely used but not statically scannable. ai
phantom-deps phantom-dep:yaml AI (phantom-deps): Bundled dist output; likely used but not statically scannable. ai
phantom-deps phantom-dep:prompts AI (phantom-deps): Bundled dist output; likely used but not statically scannable. ai
phantom-deps phantom-dep:magicast AI (phantom-deps): Bundled dist output; likely used but not statically scannable. ai
provenance publisher-changed AI (provenance): Migrated from personal account to GitHub Actions CI/CD with SLSA provenance; legitimate transition. ai
phantom-deps phantom-dep:deslop-js AI (phantom-deps): Declared dep used as a tool/plugin, not directly imported; stable pattern for this package. ai
phantom-deps phantom-dep:oxlint AI (phantom-deps): oxlint is a runtime dependency for the diagnostics engine; declared correctly. ai
phantom-deps phantom-dep:eslint-plugin-react-hooks AI (phantom-deps): eslint plugin is a runtime dependency for linting; declared correctly. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): typescript is a runtime dependency for type checking; declared correctly. ai

Versions (showing 2 of 102)

Version Deps Published
0.0.2 3 / 1
0.0.1 0 / 0

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.